A cryptographic key is often viewed simply as something an application
creates, stores in an HSM or KMS, and subsequently uses. As long as everything works,
there seems to be no reason to give it further thought. Problems arise, however, when
we need to answer simple questions: Why does this key exist? Who is responsible for it?
What is it used for? What happens if it is compromised? Who can replace it? And what
will stop working if we invalidate it?
At that point, it is no longer just about cryptography. Security, operations,
accountability, asset management, and—in some cases—regulatory requirements all
come into play. Consequently, cryptographic key management is not merely a matter
of creation and storage; it is about managing security assets throughout their entire
lifecycle.
Most of the terms used here were explained in the article "Secrets Without Secrets."
Others will be explained as the series progresses. The fundamental terminology regarding
electronic signatures, seals, and trust services is based, among other things, on the
eIDAS Regulation and its associated implementing acts.
One of the most common issues in managing cryptographic material is how it is perceived.
Organizations routinely track servers, databases, applications, network components,
accounts, and licenses as assets. However, a cryptographic key is often viewed merely
as a file stored on a server,
an object within an HSM, or a record in a KMS. Such a perspective is insufficient.
Like any other asset, a cryptographic key has an owner, a purpose, a value, a classification,
dependencies, and a lifecycle. At the same time, it possesses a crucial characteristic:
the key materialitself may be so sensitive that the organization must not expose it to
a standard asset management system. Consequently, "tracking" does not mean recording
the secret itself. Instead, the focus is on information that enables the key to be managed.
For instance, an organization should be able to answer questions such as:
In its key management methodology, NIST explicitly includes key and certificate inventories, metadata protection, access control, authentication, and other areas related to managing the lifecycle of cryptographic material. This shifts the focus from simple "key storage" to the management of cryptographic assets. It is at this point that cryptographic management begins to resemble traditional asset management. Knowing that a specific object exists is not enough; one must also understand its purpose, the associated responsibilities, its relationships, and its status. As with other methods, standardized inventories are available—specifically, the Cryptography Bill of Materials (CBOM) in the context of cryptography. Unfortunately, their current scope does not yet cover the components that require such inventories.
The situation is even more complex in a PKI environment. An organization manages more than just private keys; there is a wide range of interconnected objects:
These objects cannot be managed in isolation. For instance, the information "Certificate for
server XY" is of limited use from an asset management perspective. It is far more important
to understand the relationships between the service, the identity, the certificate, the public
and private keys, and the mechanism protecting the key. This relationship can be described
in simplified terms as follows:
service – identity – certificate – public key – private key – cryptographic module – owner – lifecycle
Such a link makes it possible to determine what happens, for example, when a specific key is
compromised or when a certificate expires.
One of the most common misconceptions in the field of PKI is confusing a certificate with a key.
A certificate is not a public key. It contains a public key along with other data and represents
a structured statement regarding the link between the public key and an identity or other attributes.
A private key, on the other hand, is secret cryptographic material. Possessing it enables the
performance of corresponding cryptographic operations, such as creating digital signatures.
From a record-keeping perspective, therefore, the certificate and the key represent two separate objects linked to one another. This link is practically significant, for instance, during certificate renewal. Renewing a certificate does not necessarily mean generating a new key. In some cases, the existing key can be used, whereas in others, it is advisable—for security or procedural reasons— to generate a new key. It is therefore important to distinguish at least between the following:
This distinction might seem like a matter of semantics. However, in the event of an incident, the difference between “renewing a certificate” and “replacing a key” is certainly not merely academic.
Another common oversimplification is viewing PKI merely as a specific technology or
the installation of a certificate authority. In reality, PKI is a combination of technical
tools, rules, and processes that enable the creation and maintenance of trusted links between
an identity, a public key, and cryptographic operations. A certificate authority is just one
component of this system.
Therefore, managing PKI involves more than just configuring individual components. Equally
important are the processes that dictate what happens to a key and a certificate throughout
their lifecycle. These include, for example:
Each such process should have a designated owner. It should also be possible to determine who can initiate the process, who approves it, who executes it, and how its execution is recorded. At this point, PKI begins to closely resemble traditional asset management.
A key may be technically managed by a PKI administrator. However, this does not automatically mean
that the administrator is the owner. The owner should be able to determine the key's purpose,
be responsible for its use, and decide on its lifecycle. The custodian, on the other hand, ensures
the technical execution of the established activities.
This distinction is important, for example, when the system owner changes or when the system is decommissioned.
If a system is being retired, simply removing the server or application is not enough.
It is also necessary to identify which cryptographic keys and certificates depend on it
and how their lifecycles should be concluded.
Without this link, a situation arises where the organization holds keys known to exist,
yet the reason for their continued existence is unclear. This is precisely one of the typical
challenges of cryptographic asset management. Therefore, it makes sense to address
the detailed division of responsibilities among the owner, custodian, administrator,
security role, and audit function separately.
Although PKI is a significant area for the use of cryptographic keys, it is certainly not the only one. Keys are used, for example, for:
In these cases, a certificate authority or a traditional PKI infrastructure may not exist. However, the need to manage key material remains. An organization still needs to know which key is being used, its purpose, who is responsible for it, where it is stored, who can use it, and what happens if it is compromised or its use is discontinued. That is precisely why it is not advisable to base key management solely on certificate tracking. Certificates represent only one part of the broader cryptographic landscape.
Key management is therefore not merely a technical discipline within PKI. PKI represents
a significant and often highly visible part of the issue, as there is a direct link between
the key, the certificate, identity, and trustworthiness. In some cases, the legal implications
of electronic signatures or seals also come into play.
However, cryptographic keys exist outside of PKI as well. From an asset management perspective, it is therefore appropriate
to view a key as a security asset with its own identity, owner, purpose,
classification, dependencies, and lifecycle. Simply put:
asset - owner - purpose - key - protection - usage - monitoring - change - rotation - invalidation - disposal
In the context of PKI, this model extends to include additional relationships:
identity - key - certificate - certification authority - trust anchor - service - process
Thus, the purpose of key management is not merely to prevent an attacker from accessing a private key.
It is equally important to know why the key exists, who is responsible for it, what depends on it, who
may use it, when it should be replaced, and what should happen when its trustworthiness or
utility comes to an end. Only by integrating cryptography, PKI, asset management, and organizational
processes does a truly managed key material infrastructure emerge.
A cryptographic key is therefore not merely a technical tool. It is an asset whose compromise
can have technical, operational, economic, and legal consequences. And just as with other critical
assets, knowing of its existence is not enough. An organization must know what it is, who owns it,
why it exists, where it is used, who may use it, and when it should cease to exist.
1. Introductory Provisions
1.1. These General Terms and Conditions are, unless otherwise agreed in writing in the contract, an integral part of all contracts relating to training organised or provided by the trainer, Jan Dušátko, IČ 434 797 66, DIČ 7208253041, with location Pod Harfou 938/58, Praha 9 (next as a „lector“).2. Creation of a contract by signing up for a course
2.1. Application means unilateral action of the client addressed to the trainer through a data box with identification euxesuf, e-mailu with address register@cryptosession.cz or register@cryptosession.info, internet pages cryptosession.cz, cryptosession.info or contact phone +420 602 427 840.3. Termination of the contract by cancellation of the application
3.1. The application may be cancelled by the ordering party via e-mail or via a data mailbox.4. Price and payment terms
4.1. By sending the application, the ordering party accepts the contract price (hereinafter referred to as the participation fee) indicated for the course.5. Training conditions
5.1. The trainer is obliged to inform the client 14 days in advance of the location and time of the training, including the start and end dates of the daily programme.6. Complaints
6.1. If the participant is grossly dissatisfied with the course, the trainer is informed of this information.7. Copyright of the provided materials
7.1. The training materials provided by the trainer in the course of the training meet the characteristics of a copyrighted work in accordance with Czech Act No 121/2000 Coll.8. Liability
8.1. The trainer does not assume responsibility for any shortcomings in the services of any third party that he uses in the training.9. Validity of the Terms
9.1 These General Terms and Conditions shall be valid and effective from 1 October 2024.Consent to the collection and processing of personal data
According to Regulation (EU) No 2016/679 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as "the Regulation"), the processor xxx (hereinafter referred to as "the Controller") processes personal data. Individual personal data that are part of the processing during specific activities at this web presentation and in the course of trade are also broken down.Information about the records of access to the web presentation
This website does not collect any cookies. The site does not use any analytical scripts of third parties (social networks, cloud providers). For these reasons, an option is also offered for displaying the map in the form of a link, where the primary source is OpenStreet and alternatives then the frequently used Maps of Seznam, a.s., or Google Maps of Google LLC Inc. The use of any of these sources is entirely at the discretion of the users of this site. The administrator is not responsible for the collection of data carried out by these companies, does not provide them with data about users and does not cooperate on the collection of data.Information about contacting the operator of the site
The form for contacting the operator of the site (administrator) contains the following personal data: name, surname, e-mail. These data are intended only for this communication, corresponding to the address of the user and are kept for the time necessary to fulfil the purpose, up to a maximum of one year, unless the user determines otherwise.Information about the order form
In case of an interest in the order form, the form contains more data, i.e. name, surname, e-mail and contact details for the organisation. These data are intended only for this communication, corresponding to the address of the user and are kept for one year, unless the user determines otherwise. In the event that a business relationship is concluded on the basis of this order, only the information required by Czech law on the basis of business relations (company name and address, bank account number, type of course and its price) will continue to be kept by the administrator.Information about the course completion document
Within the course, a course completion document is issued by the processor. This document contains the following data: student's name and surname, the name and date of the course completion and the employer's name. The information is subsequently used for the creation of a linear hash tree (non-modifiable record). This database contains only information about the provided names and company names, which may or may not correspond to reality and is maintained by the processor for possible re-issuance or verification of the document's issuance.Rights of the personal data subject
The customer or visitor of this website has the possibility to request information about the processing of personal data, the right to request access to personal data, or the right to request the correction or deletion of any data held about him. In the case of deletion, this requirement cannot be fulfilled only if it is not data strictly necessary in the course of business. The customer or visitor of this website also has the right to obtain explanations regarding the processing of his personal data if he finds out or believes that the processing is carried out in violation of the protection of his private and personal life or in violation of applicable legislation, and the right to request removal of the resulting situation and to ensure the correction.